CVE-2012-2994: High severity CoSoSys Endpoint Protector Appliace 4 vulnerability
Published Sep 18, 2012
·Updated
The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected Software
1 affected component
CoSoSys Endpoint Protector Appliace 4
Event History
Sep 18, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2994?
CVE-2012-2994 is classified as medium severity due to the potential for remote attackers to gain unauthorized access.
2
How do I fix CVE-2012-2994?
To fix CVE-2012-2994, change the default EPProot password and implement strong password policies.
3
What kind of attacks can exploit CVE-2012-2994?
CVE-2012-2994 can be exploited through brute-force attacks targeting the EPProot password.
4
Which versions of CoSoSys Endpoint Protector are affected by CVE-2012-2994?
CVE-2012-2994 affects the CoSoSys Endpoint Protector Appliance 4.
5
Is there a patch available for CVE-2012-2994?
There is no specific patch mentioned for CVE-2012-2994; however, updating the appliance and changing default passwords is recommended.